{
  "generated_from": "https://saas-ranking.com/restaurant-pos/lolly",
  "disclaimer": "Every result describes what we found at the addresses we checked on the date given. It is not a statement about what the vendor does or does not have. The score is a public transparency score, not a product or security rating.",
  "snapshot": "r103.106280",
  "snapshot_run": 103,
  "score_version": "v1",
  "vendor": {
    "name": "Lolly",
    "domain": "itslolly.com"
  },
  "category": {
    "slug": "restaurant-pos",
    "name": "Restaurant point of sale"
  },
  "score": 17,
  "band": "F",
  "measured": 12,
  "of": 12,
  "criteria": [
    {
      "key": "dpa",
      "name": "Data processing agreement",
      "weight": 3,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://itslolly.com/legal/dpa",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/dpa",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/legal/data-processing-agreement",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/data-processing-agreement",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/legal/data-processing-addendum",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/legal/gdpr",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/trust/dpa",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/privacy/dpa",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T09:27:18.969Z"
    },
    {
      "key": "subprozessoren",
      "name": "Subprocessor list",
      "weight": 3,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://itslolly.com/legal/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/sub-processors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/legal/sub-processors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/trust/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/privacy/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/legal/subprocessor-list",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T09:27:18.969Z"
    },
    {
      "key": "datenregion",
      "name": "Data location stated",
      "weight": 3,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://itslolly.com/security",
          "result": "reached, no match (HTTP 200)"
        },
        {
          "url": "https://itslolly.com/trust",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/legal/privacy",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/privacy",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/privacy-policy",
          "result": "found, but behind a sign-in"
        },
        {
          "url": "https://itslolly.com/compliance",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/legal/privacy-policy",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": "We found this behind a sign-in, so it is not published openly.",
      "measured_on": "2026-09-14T09:27:18.970Z"
    },
    {
      "key": "statusseite",
      "name": "Status page with history",
      "weight": 2,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://status.itslolly.com/",
          "result": "The name \"status.itslolly.com\" could not be resolved."
        },
        {
          "url": "https://itslolly.com/status",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com.statuspage.io/",
          "result": "Could not be fetched: fetch failed."
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T09:27:18.970Z"
    },
    {
      "key": "preise",
      "name": "Public pricing",
      "weight": 2,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://itslolly.com/pricing",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/pricing/",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/plans",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/en/pricing",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/pricing-plans",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T09:27:18.970Z"
    },
    {
      "key": "zertifizierungen",
      "name": "Certifications named",
      "weight": 1,
      "result": "found",
      "source_url": "https://www.itslolly.com/security",
      "addresses_checked": [
        {
          "url": "https://itslolly.com/security",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T09:27:18.970Z"
    },
    {
      "key": "sla",
      "name": "Uptime SLA with a figure",
      "weight": 1,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://itslolly.com/legal/sla",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/sla",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/legal/service-level-agreement",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/trust/sla",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/uptime",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/legal/uptime-sla",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T09:27:18.970Z"
    },
    {
      "key": "transport",
      "name": "HTTPS enforced with HSTS",
      "weight": 2,
      "result": "found",
      "source_url": "https://itslolly.com/",
      "addresses_checked": [
        {
          "url": "http://itslolly.com/",
          "result": "redirects to https://itslolly.com/"
        },
        {
          "url": "https://itslolly.com/",
          "result": "HSTS max-age=31536000"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "tracker_vor_einwilligung",
      "name": "No third-party tracking before consent",
      "weight": 2,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://itslolly.com/",
          "result": "third-party requests before any interaction: accounts.finsweet.com, api.zuko.io, app-widgets.jotform.io, assets.zuko.io, cdn.jotfor.ms, cdn.jsdelivr.net, cdn.prod.website-files.com, challenges.cloudflare.com, csp.withgoogle.com, d3e54v103j8qbb.cloudfront.net, events.jotform.com, form.jotform.com, pagead2.googlesyndication.com, region1.analytics.google.com, region1.google-analytics.com, stats.g.doubleclick.net, whoshouldisee.co.uk, www.google.com, www.google.de, www.googletagmanager.com, www.gstatic.com"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "security_txt",
      "name": "security.txt (RFC 9116)",
      "weight": 1,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://itslolly.com/.well-known/security.txt",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "subprozessor_meldung",
      "name": "Notice before subprocessors change",
      "weight": 2,
      "result": "not_found",
      "source_url": null,
      "addresses_checked": [
        {
          "url": "https://itslolly.com/legal/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/sub-processors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/legal/dpa",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/dpa",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/legal/data-processing-agreement",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/trust/subprocessors",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/legal/sub-processors",
          "result": "reached, no match (HTTP 404)"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "datenschutzkontakt",
      "name": "Named privacy contact",
      "weight": 1,
      "result": "found",
      "source_url": "https://www.itslolly.com/privacy-policy",
      "addresses_checked": [
        {
          "url": "https://itslolly.com/legal/privacy",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/privacy",
          "result": "reached, no match (HTTP 404)"
        },
        {
          "url": "https://itslolly.com/privacy-policy",
          "result": "found"
        }
      ],
      "note": null,
      "measured_on": "2026-09-14T09:27:18.971Z"
    }
  ],
  "details": [
    {
      "key": "datenschutzkontakt_art",
      "name": "Privacy contact",
      "value": "dedicated-address",
      "subject": null,
      "quote": "[address]@itslolly.com",
      "source_url": "https://www.itslolly.com/privacy-policy",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "cloudflare.com",
      "subject": null,
      "quote": "challenges.cloudflare.com",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "cloudfront.net",
      "subject": null,
      "quote": "d3e54v103j8qbb.cloudfront.net",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "doubleclick.net",
      "subject": null,
      "quote": "stats.g.doubleclick.net",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "finsweet.com",
      "subject": null,
      "quote": "accounts.finsweet.com",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "google-analytics.com",
      "subject": null,
      "quote": "region1.google-analytics.com",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "google.com",
      "subject": null,
      "quote": "region1.analytics.google.com, www.google.com",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "google.de",
      "subject": null,
      "quote": "www.google.de",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "googlesyndication.com",
      "subject": null,
      "quote": "pagead2.googlesyndication.com",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "googletagmanager.com",
      "subject": null,
      "quote": "www.googletagmanager.com",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "gstatic.com",
      "subject": null,
      "quote": "www.gstatic.com",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "jotfor.ms",
      "subject": null,
      "quote": "cdn.jotfor.ms",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "jotform.com",
      "subject": null,
      "quote": "events.jotform.com, form.jotform.com",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "jotform.io",
      "subject": null,
      "quote": "app-widgets.jotform.io",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "jsdelivr.net",
      "subject": null,
      "quote": "cdn.jsdelivr.net",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "website-files.com",
      "subject": null,
      "quote": "cdn.prod.website-files.com",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "whoshouldisee.co.uk",
      "subject": null,
      "quote": "whoshouldisee.co.uk",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "withgoogle.com",
      "subject": null,
      "quote": "csp.withgoogle.com",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "drittanbieter",
      "name": "Third-party host on first load",
      "value": "zuko.io",
      "subject": null,
      "quote": "api.zuko.io, assets.zuko.io",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "hsts_frist",
      "name": "HSTS max-age",
      "value": "31536000",
      "subject": null,
      "quote": "max-age=31536000; includeSubDomains; preload",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "hsts_option",
      "name": "HSTS option",
      "value": "include-subdomains",
      "subject": null,
      "quote": "max-age=31536000; includeSubDomains; preload",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "hsts_option",
      "name": "HSTS option",
      "value": "preload",
      "subject": null,
      "quote": "max-age=31536000; includeSubDomains; preload",
      "source_url": "https://itslolly.com/",
      "measured_on": "2026-09-14T09:27:18.971Z"
    },
    {
      "key": "zertifikat",
      "name": "Certification named",
      "value": "cyber-essentials",
      "subject": "anbieter",
      "quote": "Cyber Essentials & Cyber Essentials Plus We are certified under both Cyber Essentials and CE+, demonstrating strong,",
      "source_url": "https://www.itslolly.com/security",
      "measured_on": "2026-09-14T09:27:18.970Z"
    },
    {
      "key": "zertifikat",
      "name": "Certification named",
      "value": "iso-27001",
      "subject": "erwaehnt",
      "quote": "ISO/IEC 27001:2022 Information Security Management We operate in alignment with ISO/IEC 27001:2022, the internati",
      "source_url": "https://www.itslolly.com/security",
      "measured_on": "2026-09-14T09:27:18.970Z"
    },
    {
      "key": "zertifikat",
      "name": "Certification named",
      "value": "iso-9001",
      "subject": "anbieter",
      "quote": "ISO 9001:2015 Quality Management We are certified to ISO 9001:2015, demonstrating our commitment to deliveri",
      "source_url": "https://www.itslolly.com/security",
      "measured_on": "2026-09-14T09:27:18.970Z"
    },
    {
      "key": "zertifikat",
      "name": "Certification named",
      "value": "pci-dss",
      "subject": "anbieter",
      "quote": "Payment Security Lolly is fully compliant with PCI DSS v4.0 across both physical and digital payment channels.",
      "source_url": "https://www.itslolly.com/security",
      "measured_on": "2026-09-14T09:27:18.970Z"
    }
  ]
}